Skip to content

Use tar-codec by default - #22094

Merged
zanieb merged 11 commits into
release/0.13.0from
zb/0.13-tar-codec
Oct 1, 2026
Merged

zanieb merged 11 commits into
release/0.13.0from
zb/0.13-tar-codec

Conversation

@zanieb

@zanieb zanieb commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Tar archives still use astral-tokio-tar unless the tar-codec preview feature is enabled. Make tar-codec the default for extraction, uv_build source distributions, and publishing metadata, with UV_LEGACY_TAR_BACKEND=1 available for workflows that need the previous backend. Resolve the tar choice once per build context, download operation, or publishing session and pass it through archive operations. Document the stricter archive handling in the 0.13.0 changelog.

@zanieb zanieb mentioned this pull request Sep 30, 2026
@zanieb
zanieb changed the base branch from zb/0.13-changelog to zb/0.13-archive-changelog September 30, 2026 16:25
@zanieb
zanieb deployed to automations September 30, 2026 16:27 — with GitHub Actions Active
@zanieb
zanieb deployed to automations September 30, 2026 16:51 — with GitHub Actions Active
@zanieb
zanieb force-pushed the zb/0.13-archive-changelog branch from 24d2953 to aa8a131 Compare September 30, 2026 18:45
Base automatically changed from zb/0.13-archive-changelog to release/0.13.0 September 30, 2026 18:52
@zanieb
zanieb deployed to automations September 30, 2026 19:43 — with GitHub Actions Active
Comment thread crates/uv/tests/build/build_backend.rs Outdated
Comment on lines +80 to +88
let default = build(None, false)?;
let fallback = build(Some("1"), false)?;
assert_ne!(default, fallback);
assert_eq!(build(Some("true"), false)?, fallback);
assert_eq!(build(Some("0"), false)?, default);
assert_eq!(build(Some("false"), false)?, default);
assert_eq!(build(Some("invalid"), false)?, default);
assert_eq!(build(None, true)?, default);
assert_eq!(build(Some("1"), true)?, fallback);

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think we need to integration test our boolish parser here....

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like Codex didn't do this one 🙂

@codspeed

codspeed Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Merging this PR will degrade performance by 5.58%

❌ 2 regressed benchmarks
✅ 70 untouched benchmarks
⏩ 28 skipped benchmarks1

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Mode Benchmark BASE HEAD Efficiency
❌ WallTime revalidate_shared 83.9 ms 89.2 ms -5.96%
❌ WallTime create_shared[blocking] 43 ms 45.3 ms -5.2%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing zb/0.13-tar-codec (846c2de) with release/0.13.0 (364eca4)

Open in CodSpeed

Footnotes

  1. 28 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

Comment thread crates/uv-build-backend/src/lib.rs Outdated
build_with_backend(source_root, dist, TarBackend::default())
}

fn build_with_backend(

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

build_with_backend is way too confusing. Should we call it build_with_options?

)
}

pub(crate) fn build_source_dist_with_backend(

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We absolutely cannot call it build_source_dist_with_backend where backend refers to the tar backend. It's too ambiguous. Why aren't we just changing the parent API?

Comment on lines 69 to 75

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs to be an exhaustive match...

Comment thread crates/uv-extract/src/stream.rs Outdated
dst: &Path,
) -> Result<Vec<UnhashedFile>, Error> {
if uv_preview::is_enabled(PreviewFeature::TarCodec) {
if TarBackend::from_env() == TarBackend::TarCodec {

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs to be exhaustive match too.

Should this setting be threaded through instead? Are we reading from the env multiple times?

@zanieb
zanieb deployed to automations September 30, 2026 20:18 — with GitHub Actions Active
@zanieb
zanieb deployed to automations September 30, 2026 20:28 — with GitHub Actions Active
@zanieb
zanieb marked this pull request as ready for review September 30, 2026 20:42
@zanieb
zanieb deployed to automations September 30, 2026 20:48 — with GitHub Actions Active
Comment thread crates/uv-preview/src/lib.rs Outdated
Comment on lines 329 to 331
/// Deprecated compatibility feature. `tar-codec` is enabled by default; set
/// `UV_LEGACY_TAR_BACKEND=1` to use the legacy backend.
TarCodec,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't we want to delete this preview feature now?

@zanieb zanieb Sep 30, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, Codex being super annoying about this... I did ask it to in another pull request.

I think we should either delete them or say the verison they're stablized in. Not sure which is better yet.

@zanieb
zanieb deployed to automations September 30, 2026 21:06 — with GitHub Actions Active
@zanieb
zanieb deployed to automations October 1, 2026 00:09 — with GitHub Actions Active
@zanieb
zanieb merged commit f7b00e2 into release/0.13.0 Oct 1, 2026
123 of 124 checks passed
@zanieb
zanieb deleted the zb/0.13-tar-codec branch October 1, 2026 13:47
charliermarsh pushed a commit that referenced this pull request Oct 1, 2026
Tar archives still use `astral-tokio-tar` unless the `tar-codec` preview
feature is enabled. Make `tar-codec` the default for extraction,
`uv_build` source distributions, and publishing metadata, with
`UV_LEGACY_TAR_BACKEND=1` available for workflows that need the previous
backend. Resolve the tar choice once per build context, download
operation, or publishing session and pass it through archive operations.
Document the stricter archive handling in the `0.13.0` changelog.
zanieb added a commit that referenced this pull request Oct 7, 2026
Tar archives still use `astral-tokio-tar` unless the `tar-codec` preview
feature is enabled. Make `tar-codec` the default for extraction,
`uv_build` source distributions, and publishing metadata, with
`UV_LEGACY_TAR_BACKEND=1` available for workflows that need the previous
backend. Resolve the tar choice once per build context, download
operation, or publishing session and pass it through archive operations.
Document the stricter archive handling in the `0.13.0` changelog.
zanieb added a commit that referenced this pull request Oct 9, 2026
Tar archives still use `astral-tokio-tar` unless the `tar-codec` preview
feature is enabled. Make `tar-codec` the default for extraction,
`uv_build` source distributions, and publishing metadata, with
`UV_LEGACY_TAR_BACKEND=1` available for workflows that need the previous
backend. Resolve the tar choice once per build context, download
operation, or publishing session and pass it through archive operations.
Document the stricter archive handling in the `0.13.0` changelog.
astral-automations-bot Bot pushed a commit to astral-sh/uv-dev that referenced this pull request Oct 10, 2026
Tar archives still use `astral-tokio-tar` unless the `tar-codec` preview
feature is enabled. Make `tar-codec` the default for extraction,
`uv_build` source distributions, and publishing metadata, with
`UV_LEGACY_TAR_BACKEND=1` available for workflows that need the previous
backend. Resolve the tar choice once per build context, download
operation, or publishing session and pass it through archive operations.
Document the stricter archive handling in the `0.13.0` changelog.
luketainton pushed a commit to luketainton/luke_rsu that referenced this pull request Oct 10, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | stage | minor | `0.12.23` → `0.13.0` |

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.13.0`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0130)

[Compare Source](astral-sh/uv@0.12.24...0.13.0)

Released on 2026-10-09.

uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.

**We expect most users to be able to upgrade without making changes.**

While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. **uv may download or rebuild dependencies after upgrading**, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.

There are no breaking changes to the configuration of the [uv build backend](https://docs.astral.sh/uv/concepts/build-backend/). If your `[build-system]` table includes an upper bound on `uv_build`, update it to allow `uv_build` 0.13, e.g., `uv_build>=0.13.0,<0.14`.

##### Breaking changes

- **Use Python 3.15 as the default stable version**

  The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running `uv python install`.

  uv continues to use compatible Python installations that are already present. For example, `uv venv` can still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such as `uv venv` and `uvx python` can now download Python 3.15.

  You can opt out of this behavior by requesting Python 3.14 explicitly, e.g., `uv venv --python 3.14`. For projects, use `uv python pin 3.14` to record the version in `.python-version`.

- **Honor `--require-hashes` in included constraints files** ([#&#8203;22275](astral-sh/uv#22275))

  Previously, uv ignored `--require-hashes` in constraints files included with `-c` from a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.

  You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the `--require-hashes` directive from the included constraints file if hash checking is not intended.

- **Prefer native Python on Windows ARM64** ([#&#8203;22100](astral-sh/uv#22100))

  Previously, ARM64 builds of uv preferred emulated `x86_64` Python installations because native wheel support was limited. Now, uv prefers native ARM64 (`aarch64`) interpreters across Python versions.

  This follows similar changes in [CPython](https://discuss.python.org/t/python-on-windows-arm64/104524), the official Windows [Python install manager](https://discuss.python.org/t/python-install-manager-26-4/108846), and GitHub's [actions/setup-python](https://github.com/actions/setup-python#supported-architectures).

  When a native interpreter is unavailable, uv continues to fall back to `x86_64`, then 32-bit `x86`.

  You can opt out of this behavior by setting `UV_PYTHON_ARCH=x86_64` or requesting an explicit architecture, e.g., `cpython-3.14-windows-x86_64`. If you are using `setup-uv`, you can set [`python-arch: x86_64`](https://github.com/astral-sh/setup-uv#python-architecture) instead.

- **Reject editable requirements in included constraints files** ([#&#8203;22282](astral-sh/uv#22282))

  Previously, uv silently ignored editable (`-e`) requirements in constraints files included with `-c` from a requirements file. Now, uv rejects these requirements with an error, matching [pip's behavior](https://pip.pypa.io/en/stable/user_guide/#constraints-files).

  You cannot opt out of this behavior. Move editable requirements to a requirements file passed with `-r`, or pass them directly with `--editable`, instead of including them in a constraints file.

- **Omit the distutils startup patch on Python 3.10 and later** ([#&#8203;22096](astral-sh/uv#22096))

  Previously, uv installed `_virtualenv.py` and `_virtualenv.pth` into every new virtual environment to prevent distutils configuration from changing installation paths. Now, like [`virtualenv` 21.6.0](https://github.com/pypa/virtualenv/releases/tag/21.6.0), uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.

  You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.

  This stabilizes the `no-distutils-patch` preview feature.

- **Treat requirement-file option values as single paths** ([#&#8203;22290](astral-sh/uv#22290))

  Previously, uv split values passed to `--constraint`, `--override`, `--exclude`, and `--build-constraint` on spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.

  You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace `-c "a.txt b.txt"` with `-c a.txt -c b.txt`.

  Space-separated lists in `UV_CONSTRAINT`, `UV_OVERRIDE`, `UV_EXCLUDE`, and `UV_BUILD_CONSTRAINT` remain supported.

- **Use `tar-codec` for tar archives by default** ([#&#8203;22094](astral-sh/uv#22094))

  Previously, uv used `astral-tokio-tar` to extract tar archives, build source distributions with `uv_build`, and read their metadata for `uv publish`. Now, uv uses `tar-codec`, which applies stricter validation when reading archives.

  uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by `uv_build` can also have different archive bytes and hashes.

  You can opt out of this behavior by setting `UV_LEGACY_TAR_BACKEND=1`.

  This stabilizes the `tar-codec` preview feature.

- **Reject `uv build --clear` output directories that contain a build source**
  ([#&#8203;22276](astral-sh/uv#22276))

  Previously, `uv build --clear` could delete a project or input source distribution when the
  output directory contained the source. Now, uv rejects these output directories, including
  equivalent paths reached through symlinks, before clearing any build output.

  Select an output directory that does not contain any build sources, or omit `--clear`.

##### Python

- Add CPython 3.15.0 ([#&#8203;22400](astral-sh/uv#22400))

##### Preview features

- Require hashes for build dependencies, including transitive dependencies, with `--require-build-hashes` ([#&#8203;21411](astral-sh/uv#21411))

##### Performance

- Speed up revalidation of cached HTTP responses by avoiding rewrites of unchanged payloads ([#&#8203;22130](astral-sh/uv#22130))
- Reduce allocations when reading cached HTTP responses ([#&#8203;22136](astral-sh/uv#22136))
- Reduce cache storage for HTTP policies and package records ([#&#8203;22135](astral-sh/uv#22135), [#&#8203;22133](astral-sh/uv#22133))
- Reduce allocations for cached source distribution revisions ([#&#8203;22131](astral-sh/uv#22131))

##### Bug fixes

- Fix incorrect dependency resolution when reusing source metadata with different build settings ([#&#8203;22404](astral-sh/uv#22404))
- Avoid overlong wheel cache lock filenames on Windows ([#&#8203;22134](astral-sh/uv#22134))

### [`v0.12.24`](https://github.com/astral-sh/uv/releases/tag/0.12.24)

[Compare Source](astral-sh/uv@0.12.23...0.12.24)

#### Release Notes

Released on 2026-10-08.

##### Enhancements

- Remove orphaned temporary build environments with `uv cache prune` ([#&#8203;22171](astral-sh/uv#22171))
- Accept PEP 508 marker operators directly before grouped expressions ([#&#8203;22309](astral-sh/uv#22309))
- Reject malformed requirements-file options instead of partially parsing or ignoring them ([#&#8203;22317](astral-sh/uv#22317))
- Show underlying filesystem and registry errors when managed Python uninstallation fails ([#&#8203;22362](astral-sh/uv#22362))
- Identify the invalid source URL in Python mirror errors ([#&#8203;22364](astral-sh/uv#22364))

##### Preview features

- Display preferred advisory IDs in `uv audit` reports, prioritizing PYSEC, GHSA, then CVE identifiers ([#&#8203;22292](astral-sh/uv#22292))

##### Configuration

- Support custom installation mirrors for GraalPy ([#&#8203;22269](astral-sh/uv#22269))
- Support custom installation mirrors for Pyodide ([#&#8203;22271](astral-sh/uv#22271))
- Allow `UV_NO_CACHE=false` to override `no-cache = true` in configuration ([#&#8203;22324](astral-sh/uv#22324))
- Report more precise error locations for invalid trusted-host ports and preview-feature list entries ([#&#8203;22144](astral-sh/uv#22144))

##### Performance

- Speed up later commands after creating an environment by warming its interpreter cache ([#&#8203;21304](astral-sh/uv#21304))
- Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages ([#&#8203;22246](astral-sh/uv#22246))
- Enforce resource limits when parsing package indexes and `--find-links` pages with `astral-html` ([#&#8203;22203](astral-sh/uv#22203))
- Reduce standalone `uv-build` executable size by 7.5% by omitting unused Zstandard support ([#&#8203;22242](astral-sh/uv#22242))
- Reduce uv's binary size by about 232 KB by simplifying configuration deserialization ([#&#8203;22144](astral-sh/uv#22144))
- Reduce Python download error formatting code size by sharing its formatter ([#&#8203;22141](astral-sh/uv#22141))

##### Bug fixes

- Verify supplied hashes even when hash presence is disabled with `--no-require-hashes` or `require-hashes = false` ([#&#8203;22369](astral-sh/uv#22369))
- Honor exact managed Python patch pins when creating script environments instead of following patch upgrades ([#&#8203;22360](astral-sh/uv#22360))
- Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected ([#&#8203;22237](astral-sh/uv#22237))
- Exclude optional dependencies from exports when their extras are activated only in incompatible environments ([#&#8203;22234](astral-sh/uv#22234))
- Give explicit `uv publish --trusted-publishing` values precedence over configuration ([#&#8203;22279](astral-sh/uv#22279))
- Allow `UV_OFFLINE=false` to override `offline = true` in configuration ([#&#8203;22283](astral-sh/uv#22283))
- Allow `UV_SYSTEM_CERTS=false` to override `system-certs = true` in configuration ([#&#8203;22291](astral-sh/uv#22291))
- Allow `uv auth login` over IPv6 loopback addresses ([#&#8203;22306](astral-sh/uv#22306))
- Resolve GitHub dependencies whose Git references contain `#` or `%` characters ([#&#8203;22281](astral-sh/uv#22281))
- Recognize existing Pyodide interpreters as satisfying Pyodide Python requests ([#&#8203;22322](astral-sh/uv#22322))
- Preserve JSON output from `uv version` and `uv self version` with a single `--quiet` flag ([#&#8203;22280](astral-sh/uv#22280))
- Preserve trailing spaces and tabs in passwords returned by subprocess keyrings ([#&#8203;22284](astral-sh/uv#22284))
- Restore wheel incompatibility hints when `WHEEL` metadata contains multiple expanded `Tag:` rows ([#&#8203;22235](astral-sh/uv#22235))
- Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies ([#&#8203;22302](astral-sh/uv#22302))
- Prevent workspace-cache assertion failures after modifying a project at the workspace root ([#&#8203;22236](astral-sh/uv#22236))
- Hide the ignored `--keyring-provider` option from `uv auth` help ([#&#8203;19520](astral-sh/uv#19520))
- Report HTTP client setup failures directly when resolving unnamed `uv tool` requirements ([#&#8203;22320](astral-sh/uv#22320))

##### Documentation

- Update Docker and AWS Lambda examples to cache dependency layers using frozen lockfiles without project manifests ([#&#8203;22172](astral-sh/uv#22172))
- Fix stale links and descriptions in Rust crate documentation ([#&#8203;22311](astral-sh/uv#22311), [#&#8203;22361](astral-sh/uv#22361))
- Fix a typo in the `required-environments` documentation ([#&#8203;22238](astral-sh/uv#22238))

#### Install uv 0.12.24

##### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.sh | sh
```

##### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"
```

#### Download uv 0.12.24

| File                                                                                                                                                | Platform                     | Checksum                                                                                                                   |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-apple-darwin.tar.gz)                     | Apple Silicon macOS          | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-apple-darwin.tar.gz.sha256)           |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-apple-darwin.tar.gz)                       | Intel macOS                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-apple-darwin.tar.gz.sha256)            |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-pc-windows-msvc.zip)                     | ARM64 Windows                | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-pc-windows-msvc.zip.sha256)           |
| [uv-i686-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-pc-windows-msvc.zip)                           | x86 Windows                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-pc-windows-msvc.zip.sha256)              |
| [uv-x86_64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-pc-windows-msvc.zip)                       | x64 Windows                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-pc-windows-msvc.zip.sha256)            |
| [uv-aarch64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-gnu.tar.gz)           | ARM64 Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-gnu.tar.gz.sha256)      |
| [uv-i686-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-gnu.tar.gz)                 | x86 Linux                    | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-gnu.tar.gz.sha256)         |
| [uv-powerpc64le-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-powerpc64le-unknown-linux-gnu.tar.gz)   | PPC64LE Linux                | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-powerpc64le-unknown-linux-gnu.tar.gz.sha256)  |
| [uv-riscv64gc-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-gnu.tar.gz)       | RISCV Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-gnu.tar.gz.sha256)    |
| [uv-s390x-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-s390x-unknown-linux-gnu.tar.gz)               | S390x Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-s390x-unknown-linux-gnu.tar.gz.sha256)        |
| [uv-x86_64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-gnu.tar.gz)             | x64 Linux                    | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-gnu.tar.gz.sha256)       |
| [uv-armv7-unknown-linux-gnueabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-gnueabihf.tar.gz)   | ARMv7 Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-gnueabihf.tar.gz.sha256)  |
| [uv-aarch64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-musl.tar.gz)         | ARM64 MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-musl.tar.gz.sha256)     |
| [uv-i686-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-musl.tar.gz)               | x86 MUSL Linux               | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-musl.tar.gz.sha256)        |
| [uv-riscv64gc-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-musl.tar.gz)     | RISCV MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-musl.tar.gz.sha256)   |
| [uv-x86_64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-musl.tar.gz)           | x64 MUSL Linux               | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-musl.tar.gz.sha256)      |
| [uv-arm-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-arm-unknown-linux-musleabihf.tar.gz)     | ARMv6 MUSL Linux (Hardfloat) | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-arm-unknown-linux-musleabihf.tar.gz.sha256)   |
| [uv-armv7-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-musleabihf.tar.gz) | ARMv7 MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-musleabihf.tar.gz.sha256) |

#### Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):

```sh
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
```

You can also download the attestation from [GitHub](https://github.com/astral-sh/uv/attestations) and verify against that directly:

```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDguMCIsInVwZGF0ZWRJblZlciI6IjQ0LjE0OS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==-->

Reviewed-on: https://git.tainton.uk/repos/rsu/pulls/56
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton pushed a commit to luketainton/repos_labmcp that referenced this pull request Oct 10, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [ghcr.io/astral-sh/uv](https://github.com/astral-sh/uv) | final | minor | `0.12.23` → `0.13.0` |

---

### Release Notes

<details>
<summary>astral-sh/uv (ghcr.io/astral-sh/uv)</summary>

### [`v0.13.0`](https://github.com/astral-sh/uv/blob/HEAD/CHANGELOG.md#0130)

[Compare Source](astral-sh/uv@0.12.24...0.13.0)

Released on 2026-10-09.

uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.

**We expect most users to be able to upgrade without making changes.**

While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. **uv may download or rebuild dependencies after upgrading**, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.

There are no breaking changes to the configuration of the [uv build backend](https://docs.astral.sh/uv/concepts/build-backend/). If your `[build-system]` table includes an upper bound on `uv_build`, update it to allow `uv_build` 0.13, e.g., `uv_build>=0.13.0,<0.14`.

##### Breaking changes

- **Use Python 3.15 as the default stable version**

  The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running `uv python install`.

  uv continues to use compatible Python installations that are already present. For example, `uv venv` can still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such as `uv venv` and `uvx python` can now download Python 3.15.

  You can opt out of this behavior by requesting Python 3.14 explicitly, e.g., `uv venv --python 3.14`. For projects, use `uv python pin 3.14` to record the version in `.python-version`.

- **Honor `--require-hashes` in included constraints files** ([#&#8203;22275](astral-sh/uv#22275))

  Previously, uv ignored `--require-hashes` in constraints files included with `-c` from a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.

  You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the `--require-hashes` directive from the included constraints file if hash checking is not intended.

- **Prefer native Python on Windows ARM64** ([#&#8203;22100](astral-sh/uv#22100))

  Previously, ARM64 builds of uv preferred emulated `x86_64` Python installations because native wheel support was limited. Now, uv prefers native ARM64 (`aarch64`) interpreters across Python versions.

  This follows similar changes in [CPython](https://discuss.python.org/t/python-on-windows-arm64/104524), the official Windows [Python install manager](https://discuss.python.org/t/python-install-manager-26-4/108846), and GitHub's [actions/setup-python](https://github.com/actions/setup-python#supported-architectures).

  When a native interpreter is unavailable, uv continues to fall back to `x86_64`, then 32-bit `x86`.

  You can opt out of this behavior by setting `UV_PYTHON_ARCH=x86_64` or requesting an explicit architecture, e.g., `cpython-3.14-windows-x86_64`. If you are using `setup-uv`, you can set [`python-arch: x86_64`](https://github.com/astral-sh/setup-uv#python-architecture) instead.

- **Reject editable requirements in included constraints files** ([#&#8203;22282](astral-sh/uv#22282))

  Previously, uv silently ignored editable (`-e`) requirements in constraints files included with `-c` from a requirements file. Now, uv rejects these requirements with an error, matching [pip's behavior](https://pip.pypa.io/en/stable/user_guide/#constraints-files).

  You cannot opt out of this behavior. Move editable requirements to a requirements file passed with `-r`, or pass them directly with `--editable`, instead of including them in a constraints file.

- **Omit the distutils startup patch on Python 3.10 and later** ([#&#8203;22096](astral-sh/uv#22096))

  Previously, uv installed `_virtualenv.py` and `_virtualenv.pth` into every new virtual environment to prevent distutils configuration from changing installation paths. Now, like [`virtualenv` 21.6.0](https://github.com/pypa/virtualenv/releases/tag/21.6.0), uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.

  You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.

  This stabilizes the `no-distutils-patch` preview feature.

- **Treat requirement-file option values as single paths** ([#&#8203;22290](astral-sh/uv#22290))

  Previously, uv split values passed to `--constraint`, `--override`, `--exclude`, and `--build-constraint` on spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.

  You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace `-c "a.txt b.txt"` with `-c a.txt -c b.txt`.

  Space-separated lists in `UV_CONSTRAINT`, `UV_OVERRIDE`, `UV_EXCLUDE`, and `UV_BUILD_CONSTRAINT` remain supported.

- **Use `tar-codec` for tar archives by default** ([#&#8203;22094](astral-sh/uv#22094))

  Previously, uv used `astral-tokio-tar` to extract tar archives, build source distributions with `uv_build`, and read their metadata for `uv publish`. Now, uv uses `tar-codec`, which applies stricter validation when reading archives.

  uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by `uv_build` can also have different archive bytes and hashes.

  You can opt out of this behavior by setting `UV_LEGACY_TAR_BACKEND=1`.

  This stabilizes the `tar-codec` preview feature.

- **Reject `uv build --clear` output directories that contain a build source**
  ([#&#8203;22276](astral-sh/uv#22276))

  Previously, `uv build --clear` could delete a project or input source distribution when the
  output directory contained the source. Now, uv rejects these output directories, including
  equivalent paths reached through symlinks, before clearing any build output.

  Select an output directory that does not contain any build sources, or omit `--clear`.

##### Python

- Add CPython 3.15.0 ([#&#8203;22400](astral-sh/uv#22400))

##### Preview features

- Require hashes for build dependencies, including transitive dependencies, with `--require-build-hashes` ([#&#8203;21411](astral-sh/uv#21411))

##### Performance

- Speed up revalidation of cached HTTP responses by avoiding rewrites of unchanged payloads ([#&#8203;22130](astral-sh/uv#22130))
- Reduce allocations when reading cached HTTP responses ([#&#8203;22136](astral-sh/uv#22136))
- Reduce cache storage for HTTP policies and package records ([#&#8203;22135](astral-sh/uv#22135), [#&#8203;22133](astral-sh/uv#22133))
- Reduce allocations for cached source distribution revisions ([#&#8203;22131](astral-sh/uv#22131))

##### Bug fixes

- Fix incorrect dependency resolution when reusing source metadata with different build settings ([#&#8203;22404](astral-sh/uv#22404))
- Avoid overlong wheel cache lock filenames on Windows ([#&#8203;22134](astral-sh/uv#22134))

### [`v0.12.24`](https://github.com/astral-sh/uv/releases/tag/0.12.24)

[Compare Source](astral-sh/uv@0.12.23...0.12.24)

#### Release Notes

Released on 2026-10-08.

##### Enhancements

- Remove orphaned temporary build environments with `uv cache prune` ([#&#8203;22171](astral-sh/uv#22171))
- Accept PEP 508 marker operators directly before grouped expressions ([#&#8203;22309](astral-sh/uv#22309))
- Reject malformed requirements-file options instead of partially parsing or ignoring them ([#&#8203;22317](astral-sh/uv#22317))
- Show underlying filesystem and registry errors when managed Python uninstallation fails ([#&#8203;22362](astral-sh/uv#22362))
- Identify the invalid source URL in Python mirror errors ([#&#8203;22364](astral-sh/uv#22364))

##### Preview features

- Display preferred advisory IDs in `uv audit` reports, prioritizing PYSEC, GHSA, then CVE identifiers ([#&#8203;22292](astral-sh/uv#22292))

##### Configuration

- Support custom installation mirrors for GraalPy ([#&#8203;22269](astral-sh/uv#22269))
- Support custom installation mirrors for Pyodide ([#&#8203;22271](astral-sh/uv#22271))
- Allow `UV_NO_CACHE=false` to override `no-cache = true` in configuration ([#&#8203;22324](astral-sh/uv#22324))
- Report more precise error locations for invalid trusted-host ports and preview-feature list entries ([#&#8203;22144](astral-sh/uv#22144))

##### Performance

- Speed up later commands after creating an environment by warming its interpreter cache ([#&#8203;21304](astral-sh/uv#21304))
- Reduce code-signature verification work for ARM64 macOS releases with 16 KiB signature pages ([#&#8203;22246](astral-sh/uv#22246))
- Enforce resource limits when parsing package indexes and `--find-links` pages with `astral-html` ([#&#8203;22203](astral-sh/uv#22203))
- Reduce standalone `uv-build` executable size by 7.5% by omitting unused Zstandard support ([#&#8203;22242](astral-sh/uv#22242))
- Reduce uv's binary size by about 232 KB by simplifying configuration deserialization ([#&#8203;22144](astral-sh/uv#22144))
- Reduce Python download error formatting code size by sharing its formatter ([#&#8203;22141](astral-sh/uv#22141))

##### Bug fixes

- Verify supplied hashes even when hash presence is disabled with `--no-require-hashes` or `require-hashes = false` ([#&#8203;22369](astral-sh/uv#22369))
- Honor exact managed Python patch pins when creating script environments instead of following patch upgrades ([#&#8203;22360](astral-sh/uv#22360))
- Prevent dependency overrides and constraints from activating optional dependencies when their extras are not selected ([#&#8203;22237](astral-sh/uv#22237))
- Exclude optional dependencies from exports when their extras are activated only in incompatible environments ([#&#8203;22234](astral-sh/uv#22234))
- Give explicit `uv publish --trusted-publishing` values precedence over configuration ([#&#8203;22279](astral-sh/uv#22279))
- Allow `UV_OFFLINE=false` to override `offline = true` in configuration ([#&#8203;22283](astral-sh/uv#22283))
- Allow `UV_SYSTEM_CERTS=false` to override `system-certs = true` in configuration ([#&#8203;22291](astral-sh/uv#22291))
- Allow `uv auth login` over IPv6 loopback addresses ([#&#8203;22306](astral-sh/uv#22306))
- Resolve GitHub dependencies whose Git references contain `#` or `%` characters ([#&#8203;22281](astral-sh/uv#22281))
- Recognize existing Pyodide interpreters as satisfying Pyodide Python requests ([#&#8203;22322](astral-sh/uv#22322))
- Preserve JSON output from `uv version` and `uv self version` with a single `--quiet` flag ([#&#8203;22280](astral-sh/uv#22280))
- Preserve trailing spaces and tabs in passwords returned by subprocess keyrings ([#&#8203;22284](astral-sh/uv#22284))
- Restore wheel incompatibility hints when `WHEEL` metadata contains multiple expanded `Tag:` rows ([#&#8203;22235](astral-sh/uv#22235))
- Preserve Windows wheel-script rename errors unless a cross-drive copy fallback applies ([#&#8203;22302](astral-sh/uv#22302))
- Prevent workspace-cache assertion failures after modifying a project at the workspace root ([#&#8203;22236](astral-sh/uv#22236))
- Hide the ignored `--keyring-provider` option from `uv auth` help ([#&#8203;19520](astral-sh/uv#19520))
- Report HTTP client setup failures directly when resolving unnamed `uv tool` requirements ([#&#8203;22320](astral-sh/uv#22320))

##### Documentation

- Update Docker and AWS Lambda examples to cache dependency layers using frozen lockfiles without project manifests ([#&#8203;22172](astral-sh/uv#22172))
- Fix stale links and descriptions in Rust crate documentation ([#&#8203;22311](astral-sh/uv#22311), [#&#8203;22361](astral-sh/uv#22361))
- Fix a typo in the `required-environments` documentation ([#&#8203;22238](astral-sh/uv#22238))

#### Install uv 0.12.24

##### Install prebuilt binaries via shell script

```sh
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.sh | sh
```

##### Install prebuilt binaries via powershell script

```sh
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-installer.ps1 | iex"
```

#### Download uv 0.12.24

| File                                                                                                                                                | Platform                     | Checksum                                                                                                                   |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| [uv-aarch64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-apple-darwin.tar.gz)                     | Apple Silicon macOS          | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-apple-darwin.tar.gz.sha256)           |
| [uv-x86_64-apple-darwin.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-apple-darwin.tar.gz)                       | Intel macOS                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-apple-darwin.tar.gz.sha256)            |
| [uv-aarch64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-pc-windows-msvc.zip)                     | ARM64 Windows                | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-pc-windows-msvc.zip.sha256)           |
| [uv-i686-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-pc-windows-msvc.zip)                           | x86 Windows                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-pc-windows-msvc.zip.sha256)              |
| [uv-x86_64-pc-windows-msvc.zip](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-pc-windows-msvc.zip)                       | x64 Windows                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-pc-windows-msvc.zip.sha256)            |
| [uv-aarch64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-gnu.tar.gz)           | ARM64 Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-gnu.tar.gz.sha256)      |
| [uv-i686-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-gnu.tar.gz)                 | x86 Linux                    | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-gnu.tar.gz.sha256)         |
| [uv-powerpc64le-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-powerpc64le-unknown-linux-gnu.tar.gz)   | PPC64LE Linux                | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-powerpc64le-unknown-linux-gnu.tar.gz.sha256)  |
| [uv-riscv64gc-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-gnu.tar.gz)       | RISCV Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-gnu.tar.gz.sha256)    |
| [uv-s390x-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-s390x-unknown-linux-gnu.tar.gz)               | S390x Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-s390x-unknown-linux-gnu.tar.gz.sha256)        |
| [uv-x86_64-unknown-linux-gnu.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-gnu.tar.gz)             | x64 Linux                    | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-gnu.tar.gz.sha256)       |
| [uv-armv7-unknown-linux-gnueabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-gnueabihf.tar.gz)   | ARMv7 Linux                  | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-gnueabihf.tar.gz.sha256)  |
| [uv-aarch64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-musl.tar.gz)         | ARM64 MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-aarch64-unknown-linux-musl.tar.gz.sha256)     |
| [uv-i686-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-musl.tar.gz)               | x86 MUSL Linux               | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-i686-unknown-linux-musl.tar.gz.sha256)        |
| [uv-riscv64gc-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-musl.tar.gz)     | RISCV MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-riscv64gc-unknown-linux-musl.tar.gz.sha256)   |
| [uv-x86_64-unknown-linux-musl.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-musl.tar.gz)           | x64 MUSL Linux               | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-x86_64-unknown-linux-musl.tar.gz.sha256)      |
| [uv-arm-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-arm-unknown-linux-musleabihf.tar.gz)     | ARMv6 MUSL Linux (Hardfloat) | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-arm-unknown-linux-musleabihf.tar.gz.sha256)   |
| [uv-armv7-unknown-linux-musleabihf.tar.gz](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-musleabihf.tar.gz) | ARMv7 MUSL Linux             | [checksum](https://releases.astral.sh/github/uv/releases/download/0.12.24/uv-armv7-unknown-linux-musleabihf.tar.gz.sha256) |

#### Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the [GitHub CLI](https://cli.github.com/manual/gh_attestation_verify):

```sh
gh attestation verify <file-path of downloaded artifact> --repo astral-sh/uv
```

You can also download the attestation from [GitHub](https://github.com/astral-sh/uv/attestations) and verify against that directly:

```sh
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
```

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xNDguMCIsInVwZGF0ZWRJblZlciI6IjQ0LjE0OS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==-->

Reviewed-on: https://git.tainton.uk/repos/labmcp/pulls/72
Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk>

This branch was successfully deployed

1 active deployment
automations — 846c2de3 Deployed Oct 1, 2026 by zanieb via review / security review #48727
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants